Here's the problem. All seemed OK (the users were listed in Workgroup Manager and I could 'su' to users. I then tried to login as a user and could not mount the home directory. While investigating this I found that users could not create kerberos tickets (bad password). Using 'kadmin.local' and 'listprincs' I found that none of the users were in the kerberos database. Plus the last several principals listed appeared to be garbage. Has anyone run iinto this and/or can anyone suggest what I did wrong? Were the duplicate warnings a symptom or cause?
One other question that might be more important. The instructions said to change the RSA keys in the ldif file. It talked about changing all RSA keys but mentioned only the keys in the ";ApplePasswordServer;" line. I also have the same RSA key on an additional line ";KerberosV5;" so I changed that as well. Should the instructions have said to change ONLY the ";ApplePasswordServer;" lines? Do I need to re-migrate leaving those lines with the original key? Are the line endings critical? I had the :root
My hope that is one of these omissions is the culprit and someone can advise. TIA.